2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27378 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f... |
| CVE-2025-69766 | CRITICAL | 9.8 | 0.7% | Jan 21, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl... |
| CVE-2025-69763 | CRITICAL | 9.8 | 0.8% | Jan 21, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memor... |
| CVE-2025-69762 | CRITICAL | 9.8 | 0.8% | Jan 21, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory ... |
| CVE-2025-15521 | CRITICAL | 9.8 | 0.4% | Jan 21, 2026 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e... |
| CVE-2025-55130 | CRITICAL | 9.1 | 1.6% | Jan 20, 2026 | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u... |
| CVE-2025-56005 | CRITICAL | 9.8 | 17.5% | Jan 20, 2026 | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the ... |
| CVE-2025-55423 | CRITICAL | 9.8 | 3.3% | Jan 20, 2026 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr... |
| CVE-2025-65482 | CRITICAL | 9.8 | 0.5% | Jan 20, 2026 | An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitra... |
| CVE-2025-64087 | CRITICAL | 9.8 | 0.5% | Jan 20, 2026 | A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.... |
| CVE-2025-36418 | CRITICAL | 9.8 | 0.1% | Jan 20, 2026 | IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. A... |
| CVE-2025-14533 | CRITICAL | 9.8 | 1.0% | Jan 20, 2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a... |
| CVE-2025-55252 | CRITICAL | 9.8 | 0.1% | Jan 19, 2026 | HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable pas... |
| CVE-2025-55251 | CRITICAL | 9.8 | 0.2% | Jan 19, 2026 | HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re... |
| CVE-2025-52660 | CRITICAL | 9.8 | 0.3% | Jan 19, 2026 | HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re... |
| CVE-2025-11043 | CRITICAL | 9.1 | 0.2% | Jan 19, 2026 | An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio... |
| CVE-2025-10484 | CRITICAL | 9.8 | 0.4% | Jan 17, 2026 | The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B... |
| CVE-2025-15403 | CRITICAL | 9.8 | 0.5% | Jan 17, 2026 | The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6... |
| CVE-2025-14894 | CRITICAL | 9.8 | 0.6% | Jan 16, 2026 | Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not p... |
| CVE-2025-14510 | CRITICAL | 9.2 | 0.4% | Jan 16, 2026 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Abi... |
| CVE-2025-59870 | CRITICAL | 9.8 | 0.2% | Jan 16, 2026 | HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secr... |
| CVE-2025-60021 | CRITICAL | 9.8 | 26.2% | Jan 16, 2026 | Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all ... |
| CVE-2025-62582 | CRITICAL | 9.8 | 0.5% | Jan 16, 2026 | Delta Electronics DIAView has multiple vulnerabilities. |
| CVE-2025-62581 | CRITICAL | 9.8 | 0.5% | Jan 16, 2026 | Delta Electronics DIAView has multiple vulnerabilities. |
| CVE-2025-65118 | CRITICAL | 9.3 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimizatio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now